GDPR in the US: Does It Apply to American Businesses?

RS
River Starnes
Updated
GDPR in the US: does it apply to American businesses? Yes, if you handle EU data. Learn who is covered, key obligations, fines, and a compliance checklist.

GDPR in the US: Does It Apply to American Businesses?

If you run a US business and sell to, market to, or collect data from people in Europe, GDPR in the US is not a contradiction in terms. The General Data Protection Regulation is an EU law, but it reaches across borders. Any US company that processes the personal data of people located in the EU can fall under its scope, regardless of where the company is headquartered or where its servers sit. That is why "GDPR USA" is one of the most common privacy questions American eCommerce and SaaS teams ask. This guide explains exactly when GDPR applies to US businesses, what it requires, what non-compliance can cost, and a practical checklist to get compliant.

Does GDPR Apply to US Businesses?

The short answer: GDPR can apply to a US business even if it has no office, staff, or servers in Europe. The regulation is built around who you process data about, not where you are based.

Under the GDPR's extraterritorial scope (commonly referred to as Article 3), a US business is generally covered if it does either of the following:

  • Offers goods or services to people in the EU — paid or free. Signals include pricing in euros, shipping to EU countries, EU-language storefronts, or marketing aimed at EU customers.
  • Monitors the behavior of people in the EU — for example, tracking, profiling, retargeting, or analytics on EU visitors to your website.

Simply having a website that an EU resident could visit is not, on its own, enough. The question is whether you are intentionally targeting or tracking people in the EU. For most US eCommerce brands that ship internationally or run retargeting ads, the answer is yes for at least some of their audience. For a deeper walkthrough of the targeting tests, see When Does GDPR Apply to US E-Commerce Stores and How the GDPR Affects Non-EU Companies.

GDPR in the US: Key Obligations for American Companies

If GDPR applies to you, the core obligations are the same as they are for an EU-based company. The principles below sit at the heart of the regulation, and US businesses are expected to build their data practices around them.

Core data-processing principles

  • Lawful basis for processing. You must have a valid legal basis before processing personal data — consent, contractual necessity, legitimate interests, legal obligation, vital interests, or public task. Consent under GDPR must be freely given, specific, informed, and unambiguous; pre-checked boxes and bundled consent do not qualify.
  • Transparency. Tell people clearly what data you collect, why, how long you keep it, and who you share it with — typically through a privacy notice.
  • Data minimization and purpose limitation. Collect only the data you actually need, and use it only for the purposes you disclosed.
  • Security. Apply appropriate technical and organizational measures to protect personal data.

Data subject rights

GDPR gives individuals enforceable rights over their data, and you need processes to honor them. These include the right to access their data, the right to rectification, the right to erasure (the "right to be forgotten"), the right to restrict or object to processing, and the right to data portability. Handling these requests at scale is exactly what a data subject access request workflow is for — see DSAR Workflow Automation for E-commerce for how to operationalize them.

Other obligations that commonly catch US teams

  • EU representative. Companies without an EU establishment that fall under GDPR may be required to designate a representative in the EU.
  • Data Protection Officer (DPO). Required in specific cases, such as large-scale processing of sensitive data or systematic monitoring at scale.
  • Cross-border data transfers. Moving EU personal data to the US requires a valid transfer mechanism. The EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) are the most common routes — see Navigating the New EU-U.S. Data Privacy Framework for details.
  • Breach notification. GDPR sets strict timelines for reporting qualifying personal-data breaches to regulators and, in some cases, affected individuals.

What Non-Compliance Can Cost

GDPR is backed by significant enforcement powers. The regulation provides for two tiers of administrative fines, with the higher tier reaching the greater of a fixed cap or a percentage of a company's total worldwide annual turnover. Beyond fines, non-compliance can mean regulatory orders to stop processing, civil claims, and lasting reputational damage with privacy-conscious customers.

For US companies, the practical risk is less about a headline fine and more about everyday exposure: running ad pixels and analytics on EU visitors without a valid lawful basis, lacking a way to fulfill deletion requests, or transferring data to the US without a proper mechanism. For a US-focused breakdown of how to reduce that exposure, read How U.S. Companies Can Avoid GDPR Fines.

What Gets US Companies Fined: Common Violations and Enforcement Trends

Most GDPR penalties against US companies trace back to a short list of repeat mistakes:

  • Transferring EU data to the US without a valid mechanism. Sending personal data to US servers without the Data Privacy Framework, SCCs, or another safeguard is one of the most-cited violations.
  • Weak or missing consent. Firing analytics and ad pixels on EU visitors before getting clear, opt-in consent — or burying consent in pre-checked boxes — is a frequent and expensive error.
  • No valid lawful basis. Processing personal data without being able to point to a specific legal basis under Article 6.
  • Holding data too long. Regulators now fine companies for keeping personal data beyond what they need, even with no breach involved — a direct application of the storage-limitation principle.

Two enforcement trends are worth watching. First, AI training data: EU regulators are scrutinizing US firms that scrape or repurpose personal data to train machine-learning models without a lawful basis, and several high-profile investigations have followed. Second, data retention: enforcement has shifted from "did you have a breach?" toward "can you justify still holding this?" The throughline is that compliance is increasingly judged on principled, end-to-end data stewardship — not just breach response.

GDPR vs. US Privacy Laws

GDPR is not the only privacy regime US businesses have to think about. State laws like the California Consumer Privacy Act (CCPA) and its amendment, the CPRA, impose their own consent, disclosure, and opt-out requirements. The obligations overlap in places (transparency, individual rights) but differ in important ways — most notably, CCPA centers on an opt-out model for data "sales" and "sharing," while GDPR generally requires an opt-in lawful basis.

Many US eCommerce brands fall under both regimes at once. Building one program that satisfies the stricter standard is usually more efficient than maintaining separate stacks. For a side-by-side comparison, see GDPR vs. CCPA: Understanding the Difference and CCPA, CPRA & GDPR Privacy Laws Explained.

A GDPR Compliance Checklist for US Businesses

Use this as a practical starting point. It is not a substitute for legal advice, but it covers the steps most US teams need.

  1. Map your data. Identify what personal data you collect, where it comes from, where it lives, who you share it with, and why. You cannot protect or delete what you cannot find.
  2. Determine if GDPR applies. Check whether you offer goods or services to, or monitor, people in the EU. If yes for any audience segment, you are likely in scope.
  3. Establish a lawful basis for each processing activity. Document it. For most marketing and analytics tracking of EU visitors, this means valid, opt-in consent.
  4. Fix consent capture. Implement a compliant consent banner that blocks non-essential cookies and trackers until the visitor agrees, and record proof of consent. See Understanding GDPR and Cookie Consent.
  5. Update your privacy notice. Make it clear, specific, and accessible, including the GDPR rights you must honor.
  6. Stand up data subject request handling. Build a repeatable process to verify identity and fulfill access, correction, and deletion requests within GDPR timelines.
  7. Lock down cross-border transfers. Confirm you rely on a valid transfer mechanism for EU data flowing to the US.
  8. Assign accountability. Determine whether you need an EU representative or a DPO, and document data-protection responsibilities internally.
  9. Prepare for breaches. Have an incident-response and breach-notification plan ready before you need it.
  10. Review and maintain. Privacy is not a one-time project. Re-audit as your data practices, vendors, and the regulatory landscape change.

How PieEye Helps US Businesses Stay GDPR-Compliant

Most of the GDPR workload for a US eCommerce brand is operational: capturing valid consent, blocking trackers until consent is given, keeping privacy notices current, and fulfilling data subject requests on time. PieEye's GDPR compliance platform automates these pieces — consent management, DSAR handling, data mapping, and policy generation — so you can cover GDPR (and overlapping US state laws) from one place instead of stitching together point tools.

GDPR in the US comes down to a simple reality: if you touch EU personal data, the regulation reaches you, and the cost of ignoring it grows as enforcement and consumer awareness rise. Treating compliance as a standing program rather than a checkbox protects you from penalties and builds the kind of trust that privacy-conscious customers increasingly expect.

Frequently Asked Questions

Does GDPR apply to US companies?

Yes, it can. GDPR applies to a US company if it offers goods or services to people located in the EU, or if it monitors the behavior of people in the EU, regardless of where the company is based. Having no EU office or servers does not exempt you. If you ship to EU customers, run EU-targeted marketing, or track EU visitors with analytics or ad pixels, you are likely in scope for at least part of your audience.

Does GDPR apply if I only have a website and no EU office?

Possibly. The test is whether you are intentionally offering goods or services to, or monitoring, people in the EU — not where your servers or staff are. A passive website that an EU resident happens to visit is generally not enough on its own, but EU-language storefronts, euro pricing, EU shipping, or retargeting of EU visitors all point toward being in scope.

What is the difference between GDPR and CCPA for US businesses?

GDPR is an EU regulation that generally requires an opt-in lawful basis before processing personal data and grants broad individual rights. CCPA/CPRA are California laws built largely around an opt-out model for the "sale" and "sharing" of personal information. Many US eCommerce brands are subject to both. See our GDPR vs. CCPA comparison for a detailed breakdown.

What happens if a US business does not comply with GDPR?

GDPR provides for administrative fines under a two-tier structure, with the higher tier tied to a percentage of worldwide annual turnover. Regulators can also order a company to stop processing data, and non-compliance can trigger civil claims and reputational harm. For US-specific guidance on reducing this exposure, see How U.S. Companies Can Avoid GDPR Fines.

How can a US business become GDPR-compliant?

Start by mapping your data and confirming whether GDPR applies to your EU audience. Then establish a lawful basis for each processing activity, implement compliant consent capture, update your privacy notice, build a data subject request process, secure your cross-border transfers, and prepare a breach-response plan. Platforms like PieEye automate the consent, DSAR, data-mapping, and policy-generation parts of that work.

For a walkthrough of how PieEye handles GDPR compliance, book a demo.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.